# Use ecs with vpn server

**URL:** <https://discuss.elastic.co/t/use-ecs-with-vpn-server/235656>\
**Category:** Elasticsearch\
**Tags:** ecs-elastic-common-schema\
**Created:** [June 4, 2020, 12:53am UTC](https://discuss.elastic.co/t/use-ecs-with-vpn-server/235656 "2020-06-04T00:53:25Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![orsa](https://avatars.discourse-cdn.com/v4/letter/o/5daacb/32.png) [@orsa](https://discuss.elastic.co/u/orsa)\
**Post date:** [June 4, 2020, 12:53am UTC](https://discuss.elastic.co/t/use-ecs-with-vpn-server/235656/1 "2020-06-04T00:53:25Z")

</div>

Hi,  
I parse Mikrotik log vpn server and and encountered difficulties in applying the ecs for some fields.  
Exsample:  
vpn session time - the total time of VPN session  
vpn session rx bits or packets  
vpn session tx bits or packets

or can i diff client public ip and client private ip  
?

---

<div class="post-metadata">

**Author:** ![webmat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webmat/32/46191_2.png) [@webmat](https://discuss.elastic.co/u/webmat)\
**Post date:** [June 4, 2020, 12:15pm UTC](https://discuss.elastic.co/t/use-ecs-with-vpn-server/235656/2 "2020-06-04T12:15:41Z")

</div>

Hello,

In ECS we don't have a clear concept of sessions, so you couldn't capture many details about a session. For session duration, however, you can use `event.duration`. This field is meant to capture the duration of any kind of event, so if you have a log event that reports the duration of a finished session, this sounds like a good fit.

For the network transfer metrics, there's a mix of fields that could be interesting in [network](https://www.elastic.co/guide/en/ecs/current/ecs-network.html) and in [source](https://www.elastic.co/guide/en/ecs/current/ecs-source.html) and [destination](https://www.elastic.co/guide/en/ecs/current/ecs-destination.html). Here's a few ideas:

- rx bytes and packets in source.bytes and source.packets
- tx bytes and packets in destination.bytes and destination.packets
- for network address translation you can capture up to 4 addresses with source.ip, source.nat.ip, destination.ip and destination.nat.ip
- total tx bytes and packets in network.bytes and network.packets
- You may also be interested in looking into network.protocol, network.direction, network.application and a few others under `network.`

Good luck!

---

<div class="post-metadata">

**Author:** ![orsa](https://avatars.discourse-cdn.com/v4/letter/o/5daacb/32.png) [@orsa](https://discuss.elastic.co/u/orsa)\
**Post date:** [June 4, 2020, 1:42pm UTC](https://discuss.elastic.co/t/use-ecs-with-vpn-server/235656/3 "2020-06-04T13:42:34Z")

</div>

Thank you very much, you helped me a lot!

I have a clarifying question.

Is it correct to assign the address issued by the DHCP servers (private ip vpn sessions) to source.nat.ip? Or was it supposed to be so when developing?

---

<div class="post-metadata">

**Author:** ![Dain.Perkins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dain.perkins/32/41143_2.png) [@Dain.Perkins](https://discuss.elastic.co/u/Dain.Perkins)\
**Post date:** [June 4, 2020, 2:31pm UTC](https://discuss.elastic.co/t/use-ecs-with-vpn-server/235656/4 "2020-06-04T14:31:45Z")

</div>

@orsa

If you are going to use both public and private IPs use the IP of the client as source.ip, the vpn assigned ip as source.nat.ip, and populate related.ip with all 3 to make searching and pivoting easier.

thanks  
/d

---

<div class="post-metadata">

**Author:** ![webmat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webmat/32/46191_2.png) [@webmat](https://discuss.elastic.co/u/webmat)\
**Post date:** [June 4, 2020, 3:33pm UTC](https://discuss.elastic.co/t/use-ecs-with-vpn-server/235656/5 "2020-06-04T15:33:59Z")

</div>

Thanks for chiming in, @Dain.Perkins 🙂

I also want to amend something I said in my first message. While ECS doesn't have a specific fields for "sessions", if you need to capture additional details about sessions (in addition to their duration), you can still do so.

ECS defines a set of fields. But it's perfectly acceptable to have additional non-ECS fields in your events, whenever you need. Here's our recommendations on how to name custom fields to avoid conflicts with future versions of ECS:

[https://www.elastic.co/guide/en/ecs/current/ecs-custom-fields-in-ecs.html](https://www.elastic.co/guide/en/ecs/current/ecs-custom-fields-in-ecs.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 2, 2020, 3:34pm UTC](https://discuss.elastic.co/t/use-ecs-with-vpn-server/235656/6 "2020-07-02T15:34:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
